Senior Operational Security Engineer

Crown Agents Bank
Greater London, UK
13 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Application Firewall Cloud Computing Configuration Management CompTIA Security+ Cyber Security Information Leak Prevention Data Security Domainkeys Identified Mail Domain-Based Message Authentication Reporting and Conformance (DMARC) Multi-Factor Authentication Email Filtering Identity and Access Management
+14 more
Network Security Network Control Network Segmentation Remote Access Technology Phishing SAP Sales and Distribution Session Management Security Information and Event Management Single Sign-On Systems Integration EndPointSecurity Data Classification Web Filtering Malware Detection

Job description

The Senior Operational Security Engineer owns and operates the firm’s core protective and detective security controls across endpoint, network, identity and data security domains, converting multiple best-efforts operational security activities into sustainable, auditable and scalable services.

Security Operations - Endpoint & Network

  • Own and operate Endpoint Detection & Response (EDR) tooling including alert triage, threat containment and endpoint health monitoring across all firm devices.
  • Enforce endpoint security baselines, compliance checks and hardening standards across the estate.
  • Manage anti-malware controls including policy configuration, update management and alert response.
  • Configure and manage firewall and Web Application Firewall (WAF) controls, network segmentation, and remote access security.
  • Working closely with the SD and Workspace team to maintain baseline security standards across endpoint environments.
  • Own email security controls including anti-spam, anti-phishing, DMARC/DKIM/SPF and attachment scanning.
  • Manage web filtering, proxy controls and malicious URL/content blocking.

Identity & Access Management

  • Administer and manage multi-factor authentication (MFA) and single sign-on (SSO) solutions across the firm.
  • Manage Privileged Access Management (PAM/PIM) controls including PAM/PIM platform administration and privileged session management.
  • Own joiner, mover and leaver (JML) processes across all systems, ensuring timely and accurate access changes.
  • Run periodic access review and recertification cycles, ensuring least-privilege is maintained across the estate.
  • Support customer-facing access controls and authentication governance.

Data Security

  • Manage Data Loss Prevention (DLP) controls including policy configuration, alert triage and response for data exfiltration events.
  • Oversee data classification, retention, archiving and disposal controls within M365 and across the estate.
  • Support insider threat monitoring controls and escalation procedures.
  • Manage encryption standards and certificate lifecycle including monitoring, renewal and revocation

Detection & Response

  • Triage and analyse security alerts from across the tooling estate, coordinating with the SOC to ensure timely detection and response.
  • Lead threat hunting activities using XDR telemetry and threat intelligence to proactively identify attacker activity.
  • Own and maintain the XDR platform including rule management, integrations and telemetry quality.
  • Investigate security incidents, anomalous activity and SOC escalations, producing clear findings and recommendations.
  • Develop and maintain incident response runbooks covering key threat scenarios and response procedures.
  • Own ransomware readiness and business resilience testing activities, including backup validation and playbook maintenance.
  • Manage security automation and SOAR playbook development to improve detection and response efficiency.
  • Provide operational interface with the SOC, supporting SLA management and technical escalation.

Operational Reporting

  • Produce clear, accurate and timely reporting covering endpoint health, network control status, DLP alert volumes, IAM control health and incident metrics.
  • Contribute security operations data and metrics to the master CISO reporting pack.

Requirements

Degree or equivalent professional experience in a relevant technical discipline. Relevant industry certification desirable, such as SC-200, AZ-500, CompTIA Security+, GIAC (GCIA, GCED, GCIH) or CISSP. Candidates with strong hands-on experience and demonstrable technical capability will be considered regardless of formal qualification.

  • Significant hands-on experience in an operational information security or security engineering role.
  • Demonstrable experience managing EDR/AV, SIEM/XDR platforms, and network security controls including firewalls, WAF and segmentation.
  • Practical experience with identity and access management including MFA, PAM/PIM and access review processes.
  • Experience with the enterprise security solutionssuites (Endpoint, Cloud, XDR, Identity, etc) and Purview/DLP.
  • Working knowledge of PAM tooling.
  • Experience in a regulated financial services environment preferred but not essential; working knowledge of ISO 27001, NIST CSF, DORA or NYDFS Part 500 beneficial.

Ability to produce clear technical documentation, reports and evidence suitable for audit and regulatory review.

About the company

Crown Agents Bank is a vastly growing and regulated UK bank that connects emerging and frontier markets to the rest of the world, using FX and payments technology. We are transforming the way payments and FX move through emerging markets, reducing friction so that more money gets to those who need it. Emerging markets payments are usually challenging, expensive, unreliable and opaque. Our solutions help fix these pain points. Ultimately, we connect traditionally hard-to-reach regions to global financial infrastructure, giving access to the best prices and the fastest, most reliable settlement.

FX and cross-border payments are often complex and expensive, especially when operating in emerging markets. Crown Agents Bank (CAB) wraps its deep and trusted relationships and strength of network around innovative digital capabilities, and cross-border transaction banking solutions to enable fintech, corporates, governments, development organisations and banks to move money to, from, and across often hard-to-reach markets.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

2:50 min

Filtering unstructured web data for model training

Jodie Burchell · LIVE

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 · LIVE

1:03 min

Replacing traditional web navigation with prompt input forms

Patrick Reinbold Patrick Reinbold · Europe 2026 Virtual

Videos

See all

Related articles

See all